CVE-2016-8504: Yandex Browser

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.

Affected products

  • Yandex Yandex Browser: up to and including 16.6.1.30165

Published 2016-10-26. Last modified 2026-06-17.